Логотип exploitDog
bind:CVE-2024-24822
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-24822

Количество 2

Количество 2

nvd логотип

CVE-2024-24822

около 2 лет назад

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3. As a workaround, one may apply the patch manually.

CVSS3: 6.5
EPSS: Низкий
github логотип

GHSA-3rfr-mpfj-2jwq

около 2 лет назад

Pimcore Admin Classic Bundle permissions are not getting checked when working with tags

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-24822

Pimcore's Admin Classic Bundle provides a backend user interface for Pimcore. Prior to version 1.3.3, an attacker can create, delete etc. tags without having the permission to do so. A fix is available in version 1.3.3. As a workaround, one may apply the patch manually.

CVSS3: 6.5
0%
Низкий
около 2 лет назад
github логотип
GHSA-3rfr-mpfj-2jwq

Pimcore Admin Classic Bundle permissions are not getting checked when working with tags

CVSS3: 6.5
0%
Низкий
около 2 лет назад

Уязвимостей на страницу